Skip to content

chore(deps): bump requests from 2.32.5 to 2.33.0 - #473

Merged
marandaneto merged 1 commit into
mainfrom
dependabot/uv/requests-2.33.0
Apr 14, 2026
Merged

marandaneto merged 1 commit into
mainfrom
dependabot/uv/requests-2.33.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps requests from 2.32.5 to 2.33.0.

Release notes

Sourced from requests's releases.

v2.33.0

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25

Changelog

Sourced from requests's changelog.

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.
Commits
  • bc04dfd v2.33.0
  • 66d21cb Merge commit from fork
  • 8b9bc8f Move badges to top of README (#7293)
  • e331a28 Remove unused extraction call (#7292)
  • 753fd08 docs: fix FAQ grammar in httplib2 example
  • 774a0b8 docs(socks): same block as other sections
  • 9c72a41 Bump github/codeql-action from 4.33.0 to 4.34.1
  • ebf7190 Bump github/codeql-action from 4.32.0 to 4.33.0
  • 0e4ae38 docs: exclude Response.is_permanent_redirect from API docs (#7244)
  • d568f47 docs: clarify Quickstart POST example (#6960)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Mar 26, 2026
@github-actions

github-actions Bot commented Mar 26, 2026 •

Copy link
Copy Markdown
Contributor

posthog-python Compliance Report

Date: 2026-04-14 11:09:06 UTC
Duration: 159457ms

✅ All Tests Passed!

29/29 tests passed


Capture Tests

✅ 29/29 tests passed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 515ms
Format Validation.Event Has Uuid ✅ 1507ms
Format Validation.Event Has Lib Properties ✅ 1506ms
Format Validation.Distinct Id Is String ✅ 1507ms
Format Validation.Token Is Present ✅ 1506ms
Format Validation.Custom Properties Preserved ✅ 1506ms
Format Validation.Event Has Timestamp ✅ 1507ms
Retry Behavior.Retries On 503 ✅ 9517ms
Retry Behavior.Does Not Retry On 400 ✅ 3505ms
Retry Behavior.Does Not Retry On 401 ✅ 3507ms
Retry Behavior.Respects Retry After Header ✅ 9513ms
Retry Behavior.Implements Backoff ✅ 23528ms
Retry Behavior.Retries On 500 ✅ 7504ms
Retry Behavior.Retries On 502 ✅ 7511ms
Retry Behavior.Retries On 504 ✅ 7513ms
Retry Behavior.Max Retries Respected ✅ 23529ms
Deduplication.Generates Unique Uuids ✅ 1496ms
Deduplication.Preserves Uuid On Retry ✅ 7514ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 14519ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 7509ms
Deduplication.No Duplicate Events In Batch ✅ 1503ms
Deduplication.Different Events Have Different Uuids ✅ 1508ms
Compression.Sends Gzip When Enabled ✅ 1510ms
Batch Format.Uses Proper Batch Structure ✅ 1508ms
Batch Format.Flush With No Events Sends Nothing ✅ 1005ms
Batch Format.Multiple Events Batched Together ✅ 1505ms
Error Handling.Does Not Retry On 403 ✅ 3508ms
Error Handling.Does Not Retry On 413 ✅ 3508ms
Error Handling.Retries On 408 ✅ 7513ms

@dependabot
dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch from 3a33c51 to 6c3ad0a Compare April 8, 2026 17:44
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch from 6c3ad0a to 457da47 Compare April 14, 2026 11:06
@dependabot
dependabot Bot changed the base branch from master to main April 14, 2026 14:25
@dependabot
dependabot Bot requested a review from a team as a code owner April 14, 2026 14:25
@marandaneto
marandaneto merged commit 5f81548 into main Apr 14, 2026
25 of 27 checks passed
@marandaneto
marandaneto deleted the dependabot/uv/requests-2.33.0 branch April 14, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant